CVE-2026-44008Disclosure(vm2_project / vm2)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.2.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668CWE-1100

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-08); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
vm2

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-11: 1Mentions · 2026-05-14: 1Mentions · 2026-05-28: 1PoC Mentioned / Linked · 2026-05-11: 1Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-28: 105-0805-1105-1405-28
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-111
Patch1
2026-05-141
Disclosure1
2026-05-281
Patch1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Disclosure

    vm2 Node.js Sandbox ライブラリの 11 件の脆弱性:任意のコード実行などの可能性 https://iototsecnews.jp/2026/05/07/critical-vm2-node-js-library-flaws-enable-arbitrary-code-execution-attacks/ 今回の脆弱性群の主な原因は、サンドボックスとホストを繋ぐブリッジ機構において、オブジェクト参照の管理が不完全だったことにあります。 CVE-2026-26956 のように JavaScript 内部の例外処理の悪用を許すものや、 CVE-2026-43999 のように設定上のロジック不備を露呈するものにより、本来は隔離されるべきホスト側の機能へのアクセスが可能になっています。 また CVE-2026-44007 のように、特定の条件下でライブラリ自身がサンドボックス内に注入されてしまう設計上の課題も指摘されています。 CVE-2026-44008 や CVE-2026-44009 など未修正の問題も残っており、言語仕様の深層を防御することの難しさが浮き彫りにされています。ご利用のチームは、ご注意ください。 #CVE202624118 #CVE202624120 #CVE202624781 #CVE202626332 #CVE202626956 #CVE202643997 #CVE202643999 #CVE202644005 #CVE202644006 #CVE202644007 #CVE202644008 #CVE202644009 #Nodejs #vm2 #Vulnerability

    Post summary

    The article reports 11 critical vulnerabilities in the vm2 Node.js sandbox library that may allow arbitrary code execution, providing technical details of the flaws but no PoC, exploit code, or active exploitation evidence.

    01001144
    491 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-44008 | CVSS 9.8 vm2 sandbox escape in Node.js versions <3.11.2. Attackers can execute arbitrary commands on host systems via array prototype getter exploitation. Patch immediately to 3.11.2+ #CVE #PatchNow https://t.co/hzvJpQTtoj

    Post summary

    The tweet announces a critical vulnerability (CVE‑2026‑44008) in vm2 sandbox escape for Node.js <3.11.2, highlighting arbitrary command execution and urging an immediate patch to version 3.11.2+.

    0000044
    30 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    🚨 CVE-2026-44008 (vm2 ≤3.11.1, CVSS 9.8): Sandbox escape via array-species bug → OS command exec on host. WAS UNPATCHED at disclosure. Exploit primitives now circulating. Code runners, AI platforms &amp; CI/CD: upgrade to 3.11.2 NOW. #ZeroDay #NodeJS

    Post summary

    CVE‑2026‑44008 is a critical sandbox escape vulnerability that was unpatched at disclosure; its exploit primitives are now circulating, prompting an urgent upgrade to Node.js 3.11.2.

    0000062
    210 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 VM2, Sandbox Breakout, #CVE-2026-44008 (Critical) https://dailycve.com/vm2-sandbox-breakout-cve-2026-44008-critical/

    Post summary

    The snippet announces the discovery of CVE-2026-44008, a critical VM2 sandbox breakout vulnerability, but offers no PoC, exploit, or patch details.

    0000026
    198 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more